VendorsDebiandebian_linux12.0
Vulnerabilities

Debian Debian Linux 12.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

292CVEs
CVE-2023-6208
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Published 2023-11-21 · Modified
8.8EPSS 0.008
CVE-2023-6186
Link targets allow arbitrary script execution
Published 2023-12-11 · Modified
8.8EPSS 0.008
CVE-2023-37201
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Published 2023-07-05 · Modified
8.8EPSS 0.008
CVE-2023-37202
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Published 2023-07-05 · Modified
8.8EPSS 0.008
CVE-2023-37211
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Published 2023-07-05 · Modified
8.8EPSS 0.008
CVE-2023-4368
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
8.8EPSS 0.007
CVE-2023-4366
Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
8.8EPSS 0.007
CVE-2023-3422
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-06-26 · Modified
8.8EPSS 0.007
CVE-2023-4047
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
8.8EPSS 0.006
CVE-2025-62600
eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security is enabled
Published 2026-02-03 · Modified
8.6EPSS 0.004
CVE-2025-62599
eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is enabled
Published 2026-02-03 · Modified
8.6EPSS 0.004
CVE-2024-46952
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).
Published 2024-11-10 · Analyzed
8.4EPSS 0.003
CVE-2023-39947
Another heap overflow in push_back_helper
Published 2023-08-11 · Modified
8.2EPSS 0.010
CVE-2023-39945
Malformed serialized data in a data submessage leads to unhandled exception
Published 2023-08-11 · Modified
8.2EPSS 0.009
CVE-2023-39946
Heap overflow in push_back_helper due to a CDR message
Published 2023-08-11 · Modified
8.2EPSS 0.009
CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
Published 2024-07-01 · Modified
8.11 PoCEPSS 0.995
CVE-2023-4428
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-08-22 · Modified
8.1EPSS 0.113
CVE-2023-4761
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-05 · Modified
8.1EPSS 0.012
CVE-2023-41915
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
Published 2023-09-09 · Modified
8.1EPSS 0.012
CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Published 2026-04-22 · Analyzed
7.8KEVEPSS 0.999
CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
Published 2023-10-03 · Analyzed
7.8KEV1 PoCEPSS 0.814
CVE-2023-36664
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Published 2023-06-25 · Modified
7.8EPSS 0.042
CVE-2023-6377
Xorg-x11-server: out-of-bounds memory reads/writes in xkb button actions
Published 2023-12-13 · Modified
7.8EPSS 0.016
CVE-2023-4004
Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()
Published 2023-07-31 · Modified
7.8EPSS 0.009
CVE-2023-5367
Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty
Published 2023-10-25 · Modified
7.8EPSS 0.006
CVE-2023-4622
Use-after-free in Linux kernel's af_unix component
Published 2023-09-06 · Modified
7.8EPSS 0.006
CVE-2023-4206
Use-after-free in Linux kernel's net/sched: cls_route component
Published 2023-09-06 · Modified
7.8EPSS 0.006
CVE-2023-4147
Kernel: netfilter: nf_tables_newrule when adding a rule with nfta_rule_chain_id leads to use-after-free
Published 2023-08-07 · Modified
7.8EPSS 0.006
CVE-2023-40283
An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.
Published 2023-08-14 · Modified
7.8EPSS 0.006
CVE-2023-35788
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
Published 2023-06-16 · Modified
7.8EPSS 0.005
CVE-2023-3776
Use-after-free in Linux kernel's net/sched: cls_fw component
Published 2023-07-21 · Modified
7.8EPSS 0.005
CVE-2023-3090
Out-of-bounds write in Linux kernel's ipvlan network driver
Published 2023-06-28 · Modified
7.8EPSS 0.005
CVE-2023-2124
An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system.
Published 2023-05-15 · Modified
7.8EPSS 0.005
CVE-2025-38001
net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
Published 2025-06-06 · Modified
7.8EPSS 0.005
CVE-2023-3777
Use-after-free in Linux kernel's netfilter: nf_tables component
Published 2023-09-06 · Analyzed
7.8EPSS 0.004
CVE-2024-46956
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
Published 2024-11-10 · Modified
7.8EPSS 0.004
CVE-2024-46953
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
Published 2024-11-10 · Modified
7.8EPSS 0.004
CVE-2024-46951
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
Published 2024-11-10 · Modified
7.8EPSS 0.004
CVE-2023-4207
Use-after-free in Linux kernel's net/sched: cls_fw component
Published 2023-09-06 · Modified
7.8EPSS 0.003
CVE-2023-4208
Use-after-free in Linux kernel's net/sched: cls_u32 component
Published 2023-09-06 · Modified
7.8EPSS 0.003
← Prev3 / 8Next →